Common mail providers
Select Google, Microsoft, Zoho, Mailchimp, SendGrid and Amazon SES.
Combine mail providers, server IPs and DNS mechanisms into one SPF TXT record.
TXT hostname
@TXT record value
v=spf1 ~allDirect DNS mechanisms
0 / 10
Record length
11 chars
Sender authorization generator
SPF is a TXT policy at the domain root that lists servers authorized to send mail for the domain. Receivers compare the connecting IP with that policy.
This generator combines common providers, custom includes, IP addresses and optional A or MX mechanisms into one v=spf1 value and displays the visible DNS mechanism budget.
Select Google, Microsoft, Zoho, Mailchimp, SendGrid and Amazon SES.
Add IPv4 or IPv6 ranges plus optional A and MX authorization.
Count direct include, a and mx mechanisms while flagging recursive risk.
Multiple v=spf1 records cause PermError. Too many include mechanisms can exceed the ten-DNS-lookup limit and invalidate authorization.
Keep mail platforms and owned servers in one maintainable policy.
Review direct lookup mechanisms and potential recursive risk before publishing.
Use -all, ~all or ?all for the rollout stage instead of omitting all.
Find the current SPF first. If one exists, merge the mechanisms instead of adding a second record.
Include business email, marketing, ticketing and owned servers.
Authorize active sources only and remove retired platforms.
Direct count is not the full recursive count, so test after publishing.
Keep one v=spf1 TXT record at the root and verify it with the checker.
SPF evaluation expects one policy. Multiple v=spf1 records cannot be reliably combined and cause PermError.
include, a, mx, exists, redirect and deprecated ptr can trigger lookups. Includes may recurse. This tool shows the direct budget; test the deployed record for the complete count.
-all marks unauthorized sources as fail and suits a confirmed sender inventory. ~all is softfail and is often used during migration or observation.
No. SPF authenticates the envelope domain and connecting IP. DKIM and DMARC alignment are also needed to protect the visible From domain.
No. It combines input locally. Check the current DNS record first and merge it manually before publishing.
After generation, check recursive SPF behavior and the complete DKIM and DMARC chain.